legal

Data Processing Addendum

This document is being finalised with our legal counsel; contact legal@codereviewer.cloud with questions.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Techware Lab (“Processor”) and the customer (“Controller”). It applies when Techware Lab processes personal data contained in Customer Content on the Controller’s behalf while providing CodeReviewer.

1. Roles and scope

The Controller determines why and how Customer Content is processed. Techware Lab processes that personal data only as the Controller’s processor, and only to provide, secure and support the Service.

Item Description
Subject matter Providing CodeReviewer: code review, fixes, test authoring and replay, security and performance testing, spec tracking
Duration For the term of the Terms, plus the period needed to return or delete data
Categories of data subjects Controller’s users; authors and contributors named in repositories; people whose data appears in applications or databases the Controller asks us to test
Categories of personal data Names, email addresses and usernames; commit and comment metadata; personal data present in source code, test recordings, screenshots or connected databases
Special categories None intended. The Controller should not submit special-category data unless it is needed

2. Processor obligations

Techware Lab will:

  • process personal data only on the Controller’s documented instructions, including those given through Service settings, unless the law requires otherwise;
  • make sure personnel with access are bound by confidentiality;
  • apply appropriate technical and organisational measures, including encryption of stored secrets and credentials, per-organisation data isolation, role-based access control and least-privilege access by staff;
  • help the Controller, as far as is reasonable, to respond to data-subject requests and to carry out data-protection assessments;
  • notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content;
  • make available the information reasonably needed to show compliance with this DPA.

3. Sub-processors

The Controller authorises Techware Lab to engage sub-processors, including cloud hosting, AI processing and email delivery providers, to provide the Service. Techware Lab will put data-protection terms in place with each sub-processor that are at least as protective as this DPA, and remains responsible for their performance. We will keep a list of current sub-processors, available on request from privacy@codereviewer.cloud, and give notice of new sub-processors so the Controller can object on reasonable grounds.

4. International transfers

When personal data is transferred across borders, Techware Lab will use a transfer mechanism recognised by the applicable data-protection law.

5. Return and deletion

When the Service ends, and on the Controller’s request, Techware Lab will return or delete personal data in Customer Content, unless the law requires it to be kept. Requests go to support@codereviewer.cloud.

6. Audits

Techware Lab will answer reasonable written security questionnaires. Any further audit must be agreed in advance, must be reasonable in scope and timing, and is subject to confidentiality.

7. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.